CVE-2025-36940
Received Received - Intake

Use-After-Free in Fuchsia Zircon Kernel Pager Proxy

Vulnerability report for CVE-2025-36940, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-24

Last updated on: 2026-08-24

Assigner: Google Devices

Description

Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from Userspace to Kernel (AP)

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-24
Last Modified
2026-08-24
Generated
2026-08-24
AI Q&A
2026-08-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
google nest_wifi 3.78.518349

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-416 The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2025-36940 is a Use-After-Free vulnerability in the zircon kernel pager proxy of the Fuchsia operating system. This flaw could enable an attacker to escalate privileges from userspace to kernel level, granting unauthorized system access.

Detection Guidance

Detection requires checking if your Nest Wifi device is running the vulnerable firmware version 3.78.518349. Use the device's admin interface or Google Home app to verify the firmware version. If the version is 3.78.518349 or earlier, the device is vulnerable.

Impact Analysis

If exploited, this vulnerability could allow unauthorized users to gain elevated privileges on affected systems. This may lead to unauthorized access, control, or potential compromise of the device or system running the vulnerable Fuchsia kernel component.

Compliance Impact

This vulnerability could lead to unauthorized access or control of Nest Wifi devices, which may result in data breaches or unauthorized data exposure. Such incidents could potentially violate compliance requirements under GDPR (data protection) or HIPAA (health information privacy) if sensitive data is involved.

Mitigation Strategies

Ensure your Nest Wifi devices are running firmware version 3.78.518349 or later. The vulnerability was fixed via an automatic Over-the-Air (OTA) update in August 2026. Verify the update is installed by checking the device firmware version in the Nest Wifi app or web interface.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-36940. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart